PatchSiren cyber security CVE debrief
CVE-2026-19577 zephyrproject CVE debrief
An out-of-bounds read vulnerability exists in the IPv6 route forwarding functionality of Zephyr, a real-time operating system. The vulnerability occurs when the nexthop neighbor has no link-layer address, causing the `net_route_ipv6_packet()` function to access an array out of bounds. This can be exploited by an unauthenticated attacker on the same link to potentially cause a denial-of-service (DoS) or information disclosure.
- Vendor
- zephyrproject
- Product
- zephyr
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Network administrators and security teams responsible for managing and securing Zephyr-based systems should assess their exposure to this vulnerability and take necessary remediation steps.
Why it matters
CVE-2026-19577 is a high-severity vulnerability in Zephyr's IPv6 implementation that can be exploited by an unauthenticated attacker on the same link to potentially cause a denial-of-service (DoS) or information disclosure. Network administrators and security teams should assess their exposure and take necessary remediation steps.
- Potential denial-of-service (DoS) or information disclosure due to out-of-bounds read
- Verification of affected versions and patch application required
- Monitoring of network traffic for potential exploitation attempts necessary
Technical summary
The `net_route_ipv6_packet()` function in Zephyr's IPv6 implementation does not properly handle cases where the nexthop neighbor has no link-layer address. This can lead to an out-of-bounds read of approximately 2.5 KB past the end of an array. The vulnerability is reachable from the `ipv6_route_packet()` function, which is called for every received unicast IPv6 packet whose destination is not a local address on the receiving interface.
Defensive priority
High
Recommended defensive actions
- Review and apply the patch provided by the vendor
- Verify that the affected version of Zephyr is not in use
- Monitor network traffic for potential exploitation attempts
- Perform a thorough review of network configurations to ensure they are not exposed to the vulnerability
- Check for any existing compensating controls that could mitigate the vulnerability
- Inventory all assets that could be impacted and prioritize their remediation
- Track the status of remediation efforts and retest affected systems once patched
Evidence notes
The vulnerability is caused by the `net_route_ipv6_packet()` function not checking if the neighbor cache entry has a linked link-layer address before resolving it. This can lead to an out-of-bounds read of approximately 2.5 KB past the end of an array. The vulnerability is reachable from the `ipv6_route_packet()` function, which is called for every received unicast IPv6 packet whose destination is not a local address on the receiving interface.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19577 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19577
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19577 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19577
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Out-of-bounds read in IPv6 route forwarding when the nexthop neighbor has no link-layer address
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19577.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/commit/b0b0e8973d1967114adbb9ed1611d448b5a46519
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vv76-4m89-95q5
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.